Hackers remained hidden for nine months on a server holding customer information for a Queensland water supplier, highlighting the need for better cyber defense for critical infrastructure. SunWater is an Australian state-owned water supplier responsible for operating 19 major dams, 80 pumping stations and 1,600 miles of pipelines.
See also: US: Sanctions on Chatex cryptoexchange for helping hackers

See also: Hackers “hit” the bZX DeFi platform and stole $55 million in crypto
According to the annual financial audit report released yesterday by the Queensland Audit Office, SunWater was breached for nine months, with the hackers remaining unnoticed the entire time.
Although the report does not directly name the entity, ABC Australia disputed the authority and confirmed that it was SunWater.
The breach occurred between August 2020 and May 2021, and hackers managed to gain access to a webserver used to store store information from the water supplier.
It seems that the hackers were not interested in exfiltration of sensitive data, as instead they simply planted a custom malware to increase visitor traffic to an online video platform.
The audit report states that there is no evidence that the threat actors stole any customer information or financial information , and the vulnerability used by the hackers has now been patched.
See also: Hackers gained access to mySA Gov accounts
The report highlights that the actors compromised the older and more vulnerable version of the system, leaving modern and much more secure web servers untouched.
Finally, the report raises the issue of a lack of proper account security practices, such as providing users with the minimum access required to perform their tasks.
In contrast, SunWater had multiple user accounts with access to multiple systems, increasing the risk in the event of a single point of breach.
A widespread problem
Auditors reviewed the internal controls of six water authorities in Australia and found deficiencies in three without naming them specifically.
From the absence of anti-fraud safeguards that would secure financial transactions by BEC operators to the presence of numerous vulnerabilities in IT systems, the report highlighted several key issues.
In summary, the auditors found that public entities have taken positive steps based on last year's recommendations, but they must also do the following:
- Implementation of security threat detection and reporting systems
- Enable multi-factor authentication on all publicly available external systems
- Set a minimum password length of eight characters
- Security awareness training
- Implementation of procedures for identifying critical security vulnerabilities
While a financial loss is always a dire scenario, as we saw in a 2017 attack on a UK-based water supplier that lost $645,000, it is not as serious as the threat to public safety.
In February 2021, a hacker gained access to a water treatment system in Oldsmar, Florida, and attempted to increase the concentration of caustic soda in the public water supply.
This was a wake-up call for US authorities who took methodical steps to upgrade the security of these critical facilities, which are targeted more often than the public realizes.
Information source: bleepingcomputer.com
